Solved

Windows Active Directory Site Costs

Posted on 2013-01-10
5
651 Views
Last Modified: 2013-01-11
I was wondering if anyone had any recommendations on the site cost calculation.

For example: I have 3 Root Controllers,

1 = Europe
2= America
3= Canada

This is a multi-domain archeteructure so we whave over 50 child domains and 100 DCs.
The Canada domains seem to have the nearest replication topology to some of hte DC's in Europe which is causing some issues right now.

Question: In Site Cost between three Root Controllers, they are all setup to each other in sites and servcies at cost of 10 with replication of 45 minutes.

I have all the rest of the sites setup accordingly like sites in U.S. are setup to one link to the root controller in America.

So the question here is how do i make sure that all the sites in U.S. point to U.S. and etc. But seeing how my root controllers are setup, should I be changing the costs so that the U.S. sites don't get nearest path to a Europe domain controller? Any suggestions would be helpful.
0
Comment
Question by:shoris
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 57

Expert Comment

by:Mike Kline
ID: 38763238
So US, Europe, and Canada are all separate domains in the same AD forest.   What you can do is setup site links between the sites you want.

SO suppose in US you have

Main US HQ site
Remote Site 1
Remote Site 2

You could create a site link between USHQ and Site 1.  USHQ and Site 2 etc...this also all depends on your physical infrastructure.

Thanks

Mike
0
 

Author Comment

by:shoris
ID: 38763251
Yes they are all separate .. root controllers.  They way i have it today is one site link setup with all three combined with the cost of 10 and replicate 45 minutes. Clearly, I can see the Europe picks up Canada DC's cause it finds the nearest path and that i don't want.

Have created all US Servers to site link with the US Root controller. But the question i had was that all three root controllers have a site link to each other and i was wondering if i should increase that cost??

The rest of the domains are setup correctly to their respective Regional link. But even though that is setup, a controller in Europe picks up automatic connection setting to a DC in Canada, and I dont want that.
0
 
LVL 26

Accepted Solution

by:
Leon Fester earned 500 total points
ID: 38763439
The root cause of your problem is the fact that you have all 3 root domain controllers in the same site. I'm assuming they each have their own subnets for their sites?

If yes, then you need to setup the site links to only include the sites that you want to as part of your replication topology.

So while all 3 sites containig your root DCs and are in the same site links you can see this issues arising. Create a site link with US and Europe only and another with US and Canada only. This way Canada and Europe will create automatic links.

Have a read about hub-and-spoke topology vs mesh topology, with that many domains and different geographical sites, you'll probably need a hybrid configuration.
http://technet.microsoft.com/en-us/library/cc775592(v=ws.10).aspx
http://support.microsoft.com/kb/244368
http://technet.microsoft.com/en-us/library/cc749943.aspx
http://technet.microsoft.com/en-us/library/cc749916.aspx
0
 

Author Comment

by:shoris
ID: 38763782
I really appreciate your input. Makes complete sense.

Would do you think of this design then:

Root COntrollers:

US - Canada  Cost 250 and Replicate 45
US  -Europe Cost 300  andReplicate 60
CA-Euruope Cost 300 and replicate 60 minutes

multi-site - multi-site Cost 90 and 30 if needed.

What do you think?
0
 
LVL 26

Expert Comment

by:Leon Fester
ID: 38766129
Adjusting the costs like that should give you the desired replication topology.
But the actual value cannot be accurately determined without knowing your network capacity.
Here is a handy guide for calculating your costs.
http://technet.microsoft.com/en-us/library/cc782827(v=ws.10).aspx

After implementing new costs, I usually ask the Network team to monitor the line consumption to see if I'm not causing a bottleneck with my AD replication.

The replication times are also dependant on a few factors:
e.g. most root domains I've come across have been resource only domains with little or no user accounts. In this scenario, you wouldn't have many issues with user account resets or permissions changes. Ideally this domain only hosts enterprise level resources like Exchange, Lync, etc. Most changes to these domains are planned activities and project work. By default the value for intersite replication is 180 minutes.

Determining when intersite replication occursActive Directory preserves bandwidth between sites by minimizing the frequency of replication and by allowing you to schedule the availability of site links for replication. By default, intersite replication across each site link occurs every 180 minutes (3 hours). You can adjust this frequency to match your specific needs. Be aware that increasing this frequency increases the amount of bandwidth used by replication. In addition, you can schedule the availability of site links for use by replication. By default, a site link is available to carry replication traffic 24 hours a day, 7 days a week. You can limit this schedule to specific days of the week and times of day. You can, for example, schedule intersite replication so that it only occurs after normal business hours. For more information, see Configure site link replication frequency and Configure site link replication availability.

Notes

With certain restrictions, you can use the Simple Mail Transfer Protocol (SMTP) for replicating to sites that do not have a direct or reliable Internet Protocol (IP) connection. For more information, see "Active Directory Replication" at the Microsoft Windows Resource Kits Web site.

Intersite replication through a firewall or virtual private network requires some special considerations. For more information, see Active Directory at the Microsoft Web site.
http://technet.microsoft.com/en-us/library/cc759160(v=ws.10).aspx
http://technet.microsoft.com/en-us/library/cc757117(v=ws.10).aspx

One last point re: costs...Exchange 2007 and higher is reliant on AD site costs to calculate delivery routes to servers so keep this in mind if you're running Exchange 2007 or higher.
http://blogs.technet.com/b/rmilne/archive/2011/10/21/exchange-2007-amp-2010-least-cost-routing.aspx
0

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Always backup Domain, SYSVOL etc.using processes according to Microsoft Best Practices. This is meant as a disaster recovery process for small environments that did not implement backup processes and did not run a secondary domain controller that ne…
Did you know that more than 4 billion data records have been recorded as lost or stolen since 2013? It was a staggering number brought to our attention during last week’s ManageEngine webinar, where attendees received a comprehensive look at the ma…
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
This tutorial will give a short introduction and overview of Backup Exec 2012 and how to navigate and perform basic functions. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as conne…

751 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question